First published: Thu Jul 07 2022(Updated: )
<a href="https://access.redhat.com/security/cve/CVE-2022-24807">CVE-2022-24807</a> A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access. <a href="https://github.com/net-snmp/net-snmp/blob/v5.9.2/CHANGES">https://github.com/net-snmp/net-snmp/blob/v5.9.2/CHANGES</a>
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/net-snmp | <5.9.2 | 5.9.2 |
Net-SNMP | <5.9.2 | |
Fedora | =36 | |
Debian | =10.0 | |
Debian | =11.0 | |
Red Hat Enterprise Linux | =9.0 | |
redhat enterprise Linux eus | =9.2 | |
redhat enterprise Linux eus | =9.4 | |
redhat enterprise Linux for arm 64 | =9.0 | |
redhat enterprise Linux for arm 64 | =9.2_aarch64 | |
redhat enterprise Linux for arm 64 | =9.4_aarch64 | |
Red Hat Enterprise Linux for ARM64 EUS | =9.4_aarch64 | |
redhat enterprise Linux for ibm z systems | =9.0 | |
redhat enterprise Linux for ibm z systems | =9.2_s390x | |
redhat enterprise Linux for ibm z systems | =9.4_s390x | |
redhat enterprise Linux for ibm z systems eus | =9.4_s390x | |
redhat enterprise Linux for power little endian | =9.0 | |
redhat enterprise Linux for power little endian eus | =9.2_ppc64le | |
redhat enterprise Linux for power little endian eus | =9.4_ppc64le | |
redhat enterprise Linux server aus | =9.2 | |
redhat enterprise Linux server aus | =9.4 | |
redhat enterprise Linux server for power little endian update services for sap solutions | =9.2_ppc64le | |
redhat enterprise Linux server update services for sap solutions | =9.2 | |
Red Hat Enterprise Linux for SAP Solutions | =9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24807 is rated as a high-severity vulnerability due to the potential for an out-of-bounds memory access.
To fix CVE-2022-24807, upgrade the net-snmp package to version 5.9.2 or later.
CVE-2022-24807 affects systems using net-snmp versions before 5.9.2, including multiple versions of Red Hat, Debian, and Fedora.
CVE-2022-24807 is a memory corruption vulnerability caused by a malformed OID in SNMP requests.
Versions of net-snmp prior to 5.9.2 are vulnerable to CVE-2022-24807.